First published: Wed Feb 07 2018(Updated: )
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | >=6590<=6613 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17552 is a vulnerability in Zoho ManageEngine AD Manager Plus build 6590 - 6613 that allows attackers to conduct URL Redirection attacks.
CVE-2017-17552 works by allowing attackers to bypass CSRF protection or masquerade a malicious URL as trusted using the src parameter in the /LoadFrame function of Zoho ManageEngine AD Manager Plus.
The severity level of CVE-2017-17552 is high, with a severity value of 8.8.
Versions 6590 - 6613 of Zoho ManageEngine AD Manager Plus are affected by CVE-2017-17552.
To mitigate the CVE-2017-17552 vulnerability, it is recommended to update to a version of Zoho ManageEngine AD Manager Plus that is not affected by the vulnerability.